Review Security
pydantic/monty
Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses.
Applies NIST/CWE security hardening to Python and Rust code.
$ npx skills add athola/claude-night-market --skill harden -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install athola/claude-night-market harden --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/pensive/skills/harden .claude/skills/harden && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "harden" agent skill from https://github.com/athola/claude-night-market/tree/master/plugins/pensive/skills/harden into .claude/skills/harden/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "harden", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/athola/claude-night-market/tree/master/plugins/pensive/skills/hardenType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add athola/claude-night-market --skill harden -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install athola/claude-night-market harden --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/pensive/skills/harden .agents/skills/harden && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "harden" agent skill from https://github.com/athola/claude-night-market/tree/master/plugins/pensive/skills/harden into .agents/skills/harden/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "harden", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add athola/claude-night-market --skill harden -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install athola/claude-night-market harden --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/pensive/skills/harden .cursor/skills/harden && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "harden" agent skill from https://github.com/athola/claude-night-market/tree/master/plugins/pensive/skills/harden into .cursor/skills/harden/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "harden", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/athola/claude-night-market.git --path plugins/pensive/skills/harden--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add athola/claude-night-market --skill harden -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install athola/claude-night-market harden --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/pensive/skills/harden .gemini/skills/harden && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "harden" agent skill from https://github.com/athola/claude-night-market/tree/master/plugins/pensive/skills/harden into .gemini/skills/harden/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "harden", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install athola/claude-night-market hardenInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add athola/claude-night-market --skill harden -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/pensive/skills/harden .github/skills/harden && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "harden" agent skill from https://github.com/athola/claude-night-market/tree/master/plugins/pensive/skills/harden into .github/skills/harden/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "harden", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add athola/claude-night-market --skill harden -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install athola/claude-night-market harden --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/athola/claude-night-market.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/pensive/skills/harden .opencode/skills/harden && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "harden" agent skill from https://github.com/athola/claude-night-market/tree/master/plugins/pensive/skills/harden into .opencode/skills/harden/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "harden", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hardenApplies NIST/CWE security hardening to Python and Rust code.
Harden is an agent skill from athola/claude-night-market. Applies NIST/CWE security hardening to Python and Rust code. Use when auditing code for vulnerabilities or proposing concrete security remediations.
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files (for example `modules/cross-cutting.md`, `modules/frontier-checks.md` and `modules/nist-controls.md`).
It sits in Security, covering Security review. It works with Python and Rust. The repository describes itself as: 23 Claude Code plugins: TDD enforcement hooks, git/PR workflows, spec-driven development, code review, project lifecycle, fix-from-error, maintenance automation, context… The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9f3eb00. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitmakeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Harden loads about 2.7k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 936 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from athola/claude-night-market at commit 9f3eb00, republished under its MIT licence (© athola). 936 words, ~2,684 tokens.
.claude/skills/harden/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.Active security hardening: scan the existing repository for vulnerabilities and forward-facing threats, then propose concrete remediations the user can approve, defer, or file.
This skill is the engine behind /harden. It complements the
Claude Code built-in /security-review (which scans the pending
diff) by sweeping the whole repository against citation-backed
checks rather than line-level review of in-flight code.
/security-review.attune:war-room
with a security-focused panel.pensive:bug-review.harden:discovery: inventory languages, build files, hooks,
CI workflowsharden:scan-python: run python-checks.md detectors when
Python is presentharden:scan-rust: run rust-checks.md detectors when Rust
is presentharden:scan-cross-cutting: run cross-cutting.md detectors
(deps, secrets, SBOM, CI)harden:scan-frontier: run frontier-checks.md (PQC, LLM
supply chain, sandboxing)harden:nist-mapping: map findings to NIST SSDF practicesharden:proposals: for each finding above the threshold,
draft a concrete remediation per modules/proposal-shape.mdharden:approval-gate: present proposals to the user for
apply / file / defer / rejectharden:apply-and-validate: apply approved proposals as
discrete commits, re-run gates, capture evidenceharden:findings-verified: citations confirmed by
citation_verifier.pyharden:report: write reviews/harden-<date>.md and
optionally post to DiscussionsLoad modules based on what the discovery step finds.
| Detected | Load |
|---|---|
Python files (*.py, pyproject.toml) | modules/python-checks.md |
Rust files (*.rs, Cargo.toml) | modules/rust-checks.md |
| Any | modules/nist-controls.md (citation backbone) |
| Any | modules/cross-cutting.md (deps, secrets, CI) |
LLM SDK use (anthropic, openai), MCP server, post-quantum surface | modules/frontier-checks.md |
| Any with proposals enabled | modules/proposal-shape.md |
The module hub keeps the SKILL.md itself under the
estimated_tokens: 1100 budget. Detail lives in the modules.
Inventory the repo without modifying anything:
# Languages and build files
find . -type f \( -name '*.py' -o -name '*.rs' -o -name '*.sh' \) \
| head -200 > /tmp/harden-langs.txt
# Build manifests
ls pyproject.toml Cargo.toml package.json go.mod 2>/dev/null
# CI workflows and pre-commit
ls .github/workflows/ .pre-commit-config.yaml 2>/dev/null
# Hooks and Dockerfiles
find . -path ./node_modules -prune -o -type f \
\( -name 'hooks.json' -o -name 'Dockerfile*' \) -printDispatch /discovery-prefilter if the repo has > 5000 source files
to bound the scan.
For each detected language, load the matching module and run its
detector list. Each detector outputs findings with the schema
defined in modules/proposal-shape.md. The citation column is
mandatory: a finding without a NIST/CWE reference is downgraded
to "advisory" and not eligible for active proposal.
Group findings by SSDF practice (PW.4, PW.8, RV.1, etc.) and CWE
ID. The mapping table lives in modules/nist-controls.md. The
report's executive summary references SSDF practice coverage so
the audit is comparable across runs.
For each finding above the configured severity threshold, draft a
concrete remediation per modules/proposal-shape.md:
pensive:blast-radiusPresent proposals one at a time via AskUserQuestion. Default
options: apply, file as issue, defer to backlog,
reject. Auto-apply is opt-in via the --auto-apply flag and
respects a per-finding severity threshold.
Apply each approved proposal as a discrete commit:
git add <touched files>
git commit -m "harden: <finding-id> <one-line summary>"After each apply, re-run the project gates:
make test --quiet && make lint && make type-checkIf a gate fails, revert the commit (git revert HEAD --no-edit)
and downgrade the finding to "needs human design."
Write reviews/harden-<date>.md with:
If running inside a PR context, post the executive summary as a
comment via abstract:post_review_insights.
| Severity | Definition | Default disposition |
|---|---|---|
| CRITICAL | Active exploit path, RCE, credential leak | apply or file immediately |
| HIGH | Plausible exploit, missing defense-in-depth on attack surface | propose for apply |
| MEDIUM | Best-practice gap, hardening opportunity | propose for apply with --auto-apply medium |
| LOW | Style/documentation gap with security flavor | file as issue |
| ADVISORY | Pattern detected without exploit narrative | report only |
# Hardening Report — <date>
## Executive Summary
- Codebase: <repo> @ <sha>
- Languages scanned: Python (X files), Rust (Y files)
- NIST SSDF practices covered: PW.4, PW.7, PW.8, RV.1, RV.2
- CWE Top 25 hits: <count> across <distinct CWEs>
- Disposition: <N> applied, <N> filed, <N> deferred, <N> rejected
## Findings
| ID | Severity | Citation | File:Line | Disposition |
|----|----------|----------|-----------|-------------|
| H1 | CRITICAL | CWE-502, NIST SSDF PW.7 | `src/x.py:45` | applied (commit abc123) |
| H2 | HIGH | CWE-89, NIST SSDF PW.4 | `src/y.py:120` | filed (#456) |
## Per-finding detail
### H1 — Unsafe deserialization
**Citation:** CWE-502 (Deserialization of Untrusted Data),
NIST SSDF PW.7 (Review and analyze human-readable code).
**Detection signal:**
- File: `src/x.py:45`
- Anchor: `data = pickle.loads(user_supplied_input)`
- Pattern: <module>.loads(user_supplied_input)
- Reachability: untrusted, comes from request body
**Proposal:** ...
**Blast radius:** ...
**Reversal plan:** ...--auto-apply,
CRITICAL findings always prompt.--report-only until the user has reviewed at least one
report and explicitly opts into proposals.The skill composes (rather than re-implements):
pensive:rust-review: full Rust audit when Rust is presentpensive:bug-review: bug-hunting backbonepensive:safety-critical-patterns: NASA Power-of-10 adaptedpensive:tiered-audit: three-tier discipline (--tier 1/2/3)pensive:blast-radius: change-impact assessment for proposalsleyline:supply-chain-advisory: dependency postureleyline:authentication-patterns: auth/credential reviewleyline:content-sanitization: input handlingabstract:hook-authoring: hook-event securityimbue:proof-of-work: evidence discipline for findingsharden:findings-verified)Write findings to .review/findings.json, run the citation verifier
(Skill(imbue:review-core) Step 5), and drop or label UNVERIFIED any
the verifier rejects.
--auto-apply flag covering its severity).reviews/harden-<date>.md exists and lists every finding
with a disposition (applied / filed / deferred / rejected /
advisory).Location + verbatim Anchor
confirmed by citation_verifier.py (exit 0), or unverified
findings were dropped or labeled UNVERIFIED.© athola, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files in plugins/pensive/skills/harden of athola/claude-night-market.
Open the folder on GitHubat commit 9f3eb00
Harden next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Harden this skillathola/claude-night-market | 341 | — | ~2.7k | Automated safety check: Pass | MIT | |
| Review Securitypydantic/monty | 8.6k | — | ~852 | Automated safety check: Pass | MIT | |
| Pyspector Security AuditParzivalHack/PySpector | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | |
| Security AuditTheDecipherist/claude-code-mastery | 551 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Security Reviewgithub/awesome-copilot | 40k | 1 repos | ~2.3k | Automated safety check: Notes | MIT | |
| Common Security AuditHoangNguyen0403/agent-skills-standard | 572 | — | ~977 | Automated safety check: Pass | MIT |
pydantic/monty
Security review of the current branch against its merge base — sandbox escapes, memory errors, panics and resource-limit bypasses.
ParzivalHack/PySpector
Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
github/awesome-copilot
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…
HoangNguyen0403/agent-skills-standard
Probe for hardcoded secrets, injection surfaces, unguarded routes, business logic flaws, and platform-specific weaknesses across backend (Node, Go, Java, Python, Rust), frontend (React, Angular…
andrew-yangy/gru-ai
Provides comprehensive code review guidance for React 19, Vue 3, Rust, TypeScript, Java, Python, and C/C++.
athola/claude-night-market
Run and interpret repo diagnostic scripts (ratchets, validators, token stats).
athola/claude-night-market
Evaluate Claude skill quality through auditing. An agent skill from athola/claude-night-market.
athola/claude-night-market
Coordinates Claude agent teams via filesystem protocol. An agent skill from athola/claude-night-market.
athola/claude-night-market
Delegates execution to eight CLIs (Gemini, Qwen, MiniMax, GLM, Muse, Codex, OpenCode, Glimmer).
athola/claude-night-market
Guide minimal code via a decision ladder with full safety, edge, and negative-case coverage.
athola/claude-night-market
Build a project skill library in .claude/skills/ via discovery, parallel authoring, and review.
Categories
Applies NIST/CWE security hardening to Python and Rust code. Harden is an agent skill from athola/claude-night-market. Applies NIST/CWE security hardening to Python and Rust code.
Harden fits situations like: auditing code for vulnerabilities; proposing concrete security remediations.
Run `npx skills add athola/claude-night-market --skill harden -a claude-code`. Or copy the skill folder (plugins/pensive/skills/harden in athola/claude-night-market) into .claude/skills/harden in your project. Claude Code loads it when a task matches its description.
Run `npx skills add athola/claude-night-market --skill harden -a codex`. Or copy the skill folder (plugins/pensive/skills/harden in athola/claude-night-market) into .agents/skills/harden in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add athola/claude-night-market --skill harden -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/harden, .gemini/skills/harden, .github/skills/harden and .opencode/skills/harden in your project.
Going by SKILL.md and its folder, Harden needs the command-line tools its instructions call (git and make). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Harden is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Harden: Review Security (pydantic/monty, 8.6k stars), Pyspector Security Audit (ParzivalHack/PySpector, 151 stars), Security Audit (TheDecipherist/claude-code-mastery, 551 stars) and Security Review (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
athola (a GitHub user) maintains it in athola/claude-night-market, which has 341 GitHub stars. The repository holds 152 skills in this directory. The repository was last updated on October 9, 2026.
Source: athola/claude-night-market on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.